Privacy at Aura
Privacy Policy
Effective August 6, 2026
Aura is designed so your detailed migraine and health-context records remain in app storage on your device or in the private CloudKit database associated with your iCloud account. Aura does not use that sensitive health context for advertising or marketing.
Scope
Aura is operated by Orion Designs LLC (“Orion,” “we,” or “us”). This policy covers the Aura iPhone app and Aura’s public website. The website has no account, health-data entry, or checkout. The app does not ask you to create a separate Aura account; when iCloud is available, app records are associated with your Apple Account through Apple’s private CloudKit service.
Records you add to Aura
Aura can store information you enter about migraine episodes, symptoms, severity, aura, pain location, possible triggers, functional impact, notes, medications, supplements, schedules, doses, treatment outcomes, prescribing clinicians, treatment photos, cycle context, travel, and preferences.
These records are stored in Aura’s protected app storage. If you use iCloud, Apple syncs them through Aura’s private CloudKit database so they can remain available across your devices. Aura does not operate its own server database containing these detailed records.
Optional Apple sources and features
You control whether to use optional Apple sources and features. Aura requests Health, Location Services, Calendar, Camera, or notification permission only when the related feature needs it. Apple’s photo picker shares only the photo you select, without giving Aura broad access to your photo library.
- Health: Aura reads selected Health data. Raw Health samples remain in Apple Health; Aura stores daily aggregates such as sleep, heart rate, heart-rate variability, daylight, state of mind, and optional cycle indicators.
- Weather and location: Aura briefly processes your location, rounds it to roughly a neighborhood-sized area, and sends the rounded coordinate to Apple WeatherKit. Aura stores resulting context such as pressure and UV, not the coordinate itself.
- Calendar: If you grant full Calendar access, Aura examines event titles and dates to identify likely travel and stores matched travel details such as title, dates, and time-zone context.
- Photos and Camera: Aura processes only the treatment photo you select or take and saves a reduced copy with the treatment record.
You can change these permissions in Aura or iOS Settings. Turning off a permission stops future access but does not automatically remove information Aura already stored from that source.
On-device analysis
Aura’s pattern analysis and personalized model run on your device. Model inputs use daily aggregates rather than raw Health samples, exact location, or full Calendar contents. Personalized model files remain in protected app storage scoped to your iCloud account or local-only profile.
Subscriptions and purchases
Purchases are completed by Apple. RevenueCat processes a pseudonymous app-user identifier, limited device and app information, and subscription details such as product identifier, purchase and renewal status, expiration, cancellation, billing issue, and refund state. Aura uses this information to unlock Premium, restore purchases, and understand subscription performance. Aura does not operate a web checkout, and RevenueCat does not receive Aura’s migraine or health-context records.
Marketing measurement
Marketing measurement is enabled by default and can be turned off at any time in Aura Settings. While enabled, AppsFlyer may process ordinary install, session, campaign, network, and app/device technical information together with a pseudonymous AppsFlyer identifier.
Aura explicitly sends only a small allowlist of app-interaction events: onboarding started, paywall viewed, onboarding completed, trial started, and paid subscription started. Event properties are limited to product identifier, offer type, app version, and timestamp.
Aura asks for App Tracking Transparency permission before AppsFlyer’s first measurement session. If you grant permission, the standard AppsFlyer SDK may collect Apple’s advertising identifier (IDFA). AppsFlyer also collects Apple’s identifier for vendors (IDFV). If permission is denied or restricted, IDFA is unavailable and attribution continues through IDFV, Apple’s SKAdNetwork and AdAttributionKit, and aggregate or modeled reporting. While measurement is enabled, AppsFlyer’s generated identifier may be supplied to RevenueCat to connect subscription lifecycle events with campaign reporting.
Your marketing choice
Turning off Marketing measurement stops future AppsFlyer measurement from Aura and removes future AppsFlyer attribution sharing from RevenueCat. It does not require those providers to erase information they processed before you turned it off. RevenueCat remains active only for purchase processing, subscription access, and restores.
Sensitive information is not used for marketing
Aura does not include migraine symptoms, medications, treatment photos, Health data, cycle information, weather context, Calendar details, pain-map selections, notes, or location in AppsFlyer events, RevenueCat customer attributes, advertising audiences, or ad-network payloads.
Website visits
Aura’s website does not include forms, user accounts, payment collection, advertising cookies, or an Aura-added analytics service. Like most websites, its hosting provider may process technical request data such as IP address, browser and device type, requested page, and timestamp to deliver and protect the site.
Exports, notifications, and system surfaces
If you export or share a report, CSV, or backup, Aura hands the file to the destination you choose through Apple’s share sheet. That file may contain sensitive health information. After you share it, the recipient, app, or storage provider controls its copy.
Notifications, widgets, shortcuts, and Live Activities can show migraine or medication information outside the open app. You can manage those surfaces and their lock-screen visibility in Aura and iOS Settings.
Service providers
Apple, RevenueCat, AppsFlyer, and the website hosting provider process their limited data under their own security, location, and retention practices. Aura requires service providers to protect data consistently with this policy, their agreements, and applicable law. You can review the providers’ policies at Apple Privacy, RevenueCat Privacy, and AppsFlyer Services Privacy.
Retention and deletion
Records in Aura remain until they are removed through controls Aura makes available, through Apple’s storage controls, or under Apple’s iCloud behavior. Aura does not currently offer one global delete control, and some derived values cannot be deleted individually in the app. Resetting Aura’s onboarding does not delete CloudKit records; deleting the app may not delete records already stored in iCloud.
Limited local preferences and event-deduplication markers remain only as needed to operate the app and honor your choices. RevenueCat, AppsFlyer, Apple, and the website host retain the data they process according to their own policies and legal obligations.
Security
Aura uses iOS file protection, Apple’s private CloudKit database, and data minimization to protect your records. No storage or transmission method is completely secure, so Aura cannot guarantee absolute security or uninterrupted synchronization.
Your choices and privacy rights
You can change data permissions in iOS Settings, turn Marketing measurement off in Aura Settings, edit or delete individual Aura records where the app provides those controls, manage iCloud app storage through Apple, and choose whether to export or share information. Depending on where you live, applicable law may also give you rights concerning personal data held by Aura’s service providers.
Changes and contact
We may update this policy as Aura changes. The effective date above will be revised when we do. Privacy questions and requests can be sent to aurasupport@joinmetric.com.
Please also read Aura’s Terms of Service.